Status — in design. Nothing is shipped, nothing is sold, and there is no customer. This page will say so when that changes.
A receipt answers one question about a sentence an AI produced: where did this come from?
Not a guess at the source. A signed statement that this span of text matches a specific document, at a specific offset, under a specific corpus, at a specific time.
span matches doc_018 @ offset 1180under corpus root 7b195c6d · signed · 2026-08-30Why a claim is not enough
An AI system saying “I based this on your policy documents” is an assertion. It cannot be checked, it cannot be produced in a dispute, and it is worth exactly as much as the trust you already had.
A receipt is different in one specific way: it can be verified by someone who does not trust you, including after the fact, including by an opposing party.
What it does not prove
It does not prove the output is correct, or reasonable, or safe. It proves attribution — that this text corresponds to that source under that corpus at that time. A model can quote a document accurately and still be wrong about what the document means.
That boundary is deliberate. A receipt that claimed to certify correctness would be the kind of overreaching instrument this whole practice exists to argue against.
What we did not invent
The attribution capability underneath this is already open source — infini-gram and OLMoTrace, Apache-2.0, and it is Ai2’s work, credited as theirs.
The receipt layer is the product: the cryptographic tamper-evidence and the compliance packaging around it. We say that plainly, including the part where the hard search problem was solved by somebody else.